Log inSign up
Microsoft Threat Intelligence
Microsoft Security
5,937 posts
Microsoft Threat Intelligence profile banner
@MsftSecIntel

Microsoft Threat Intelligence

Microsoft Security
@MsftSecIntel
We are Microsoft's global network of security experts. Follow for security research and threat intelligence.
Redmond, WA
aka.ms/threatintelblog
Joined November 2010
994
Following
197.2K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @MsftSecIntel
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    1h
    The September 2026 security updates are available. In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/6012aXv5M
    @msftsecresponse
    Microsoft Security Response Center
    Microsoft Security
    @msftsecresponse
    1h
    Security updates for September are now available: msft.it/6018SZEg0. Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent,
    Image
    1
  • @MsftSecIntel
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Sep 3
    Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII smuggling, to obscure financial lure words before email filters parsed them.
    Image
    ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog
    From microsoft.com
    9
  • @MsftSecIntel
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Sep 2
    Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2.
    Image
    Impersonating IT support: how threat actors turn a remote session into enterprise-wide access |...
    From microsoft.com
    3
  • @MsftSecIntel
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Sep 1
    Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/6011aTt3H Once executed,
    Image
    Counterfeit installers to system compromise: Tracking a deceptive software download campaign |...
    From microsoft.com
    2
  • @MsftSecIntel
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Aug 28
    Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host. This TerminalFix campaign uses fake CAPTCHA verification
    Image
    3
Advertisement
Advertisement